News

Kertos Ranks #20 in the Sifted 100 and Takes the EU Lead in Compliance Automation

248.91% two-year revenue growth against a cohort average of 157.61%, and the only compliance platform among the 100 companies ranked.

Author
Andy Mura
Date
16.9.2026
Updated on
16.9.2026
Kertos Ranks #20 in the Sifted 100 and Takes the EU Lead in Compliance Automation

Across Sifted's five European leaderboards for 2026, covering the UK and Ireland, Southern Europe, France and Benelux, the Nordics, and DACH and CEE, Kertos is the highest-ranked compliance platform for information security and data protection headquartered in the European Union. The number behind that position comes from a third party.

Kertos placed 20th in the Sifted 100: DACH & CEE 2026, the annual leaderboard of the fastest-growing startups in German-speaking and Central and Eastern Europe, with a two-year revenue compound annual growth rate of 248.91%. The ranking was published in September 2026.

One detail matters as much as the placement. Kertos is the only company among the 100 that Sifted classifies as privacy tech, and no other platform for information security and data protection compliance appears anywhere on the list.

The category itself used to be dominated by US providers focused on North American compliance frameworks. The European position was open.

The numbers behind the ranking

Kertos placed 20th of 100 with 248.91% two-year revenue growth, against a cohort average of 157.61%. Sifted describes the company as an automated data privacy and compliance automation platform for modern software teams.

Kertos was founded in Munich in 2021, employs 32 people, and has raised 20 million euros in total, most recently a 14 million euro Series A in September 2025 led by Portage, with Pilabs, Redstone, 10x Founders and seed+speed Ventures participating.

MetricKertosSifted 100 cohort
Rank20 of 100
Two-year revenue CAGR248.91%157.61% average
Employees32 (When the list was created. >75 now.)91 average
Total funding€20m
HeadquartersMunichBerlin 24%, Tallinn 11%, Munich 10%
SectorB2B SaaS, privacy tech, RegtechB2B SaaS, 32% of the ranking

Three companies in the ranking grew faster than 500%, led by Prague-based lender Flowpay at 816.31%. Another 17 sit between 250% and 500%, and 33 between 100% and 250%. Germany accounts for 41 of the 100 companies, with Estonia and Poland contributing 11 each.

"I am proud of the number, and prouder of how we got there, because none of it happened by accident. Compliance automation used to be dominated by providers optimized for North American frameworks. The European counterpart had to be built the other way around, with European frameworks first and data sovereignty by default. That is the position we set out to take when we started in Munich in 2021."
Dr. Kilian Schmidt, CEO of Kertos

How Sifted built the leaderboard

Sifted ranks on a single metric: percentage revenue growth over the past three financial years, expressed as a two-year compound annual growth rate. Funding raised, headcount and brand carry no weight in the placement.

Eligibility was narrow. Companies had to be private and independent, headquartered in one of 25 listed countries, founded no earlier than 2010, and generating most of their revenue from proprietary technology. They needed three years of revenue data, at least 50,000 euros of revenue in the base year and at least 500,000 euros in the most recent financial year, and they had to submit signed documentation supporting every figure disclosed.

Applications ran from January 1 to August 31, 2026, with research carried out by the Sifted Intelligence team. Sifted notes in the report that the leaderboard is not exhaustive, because private company data is difficult to acquire, and that historical growth guarantees nothing about future performance.

Why compliance automation is outgrowing the market around it

The regulatory surface facing a European technology company has expanded faster than the teams responsible for covering it. NIS2 pulled tens of thousands of mid-sized companies into a cybersecurity regime that previously applied mainly to critical infrastructure, and enforcement of the rollout itself is now live: in July 2026 the European Commission referred four member states to the Court of Justice for failing to notify full transposition, as set out in the official announcement.

Germany's implementation took effect on December 6, 2025. By June 30, 2026, the Federal Office for Information Security counted 17,729 registered companies, according to the authority's own figures. Government estimates put the number of entities actually in scope closer to 30,000, which leaves a registration gap in the thousands and a large population of companies that have not yet started.

Certification demand has moved in the same direction from the commercial side. ISO 27001 certification increasingly arrives as a condition of a first enterprise contract rather than a formality afterward, and SOC 2, TISAX and C5 turn up in the same procurement questionnaires, each with its own evidence requirements and audit cycle.

Artificial intelligence pushes from both directions at once. The EU AI Act added a new layer for companies building or deploying AI systems, with prohibitions and AI literacy obligations applying since February 2025 and general-purpose AI rules since August 2025. The high-risk deadlines have since moved. Regulation (EU) 2026/1744, the Digital Omnibus on AI, in force since July 27, 2026, pushed Annex III high-risk obligations to December 2027 and Annex I to August 2028, as published in the Official Journal. Even with that extension, companies building AI systems now have a fixed compliance horizon to plan against, and ISO 42001 gives them a management standard to certify to.

At the same time, AI changed the economics of the work itself. Evidence collection, control mapping across frameworks and policy upkeep used to be a consultant's annual project. An agentic system can run those tasks continuously, which lowers the cost of serving demand at the moment demand is rising. That combination, rising obligation and falling delivery cost, is the tailwind underneath the governance, risk and compliance category, and it is visible in the growth rate that put Kertos on this leaderboard.

The European position was unclaimed

Compliance automation as a software category was built in North America, for North American buyers, around SOC 2 first. European frameworks were added afterward. For a company in Munich, Amsterdam or Stockholm, that ordering shows. NIS2 requirements, GDPR records of processing, C5 and TISAX are where the work starts, and the audit evidence has to satisfy supervisory authorities that enforce locally.

Kertos was built the other way around. The platform covers ISO 27001, ISO 27701, ISO 42001, GDPR, NIS2, the EU AI Act, SOC 2, TISAX and C5, and it runs on European infrastructure with data sovereignty rather than data residency alone. KAIA, the company's agentic platform, handles the continuous work. Certified experts, including external CISO and DPO mandates, carry the judgment and sit on the customer's side of the table during the audit.

Company-reported figures put the audit pass rate at 100% and the reduction in manual compliance effort at roughly 80%. Among its customer success stories, Kertos cites AskUI, which reached ISO 27001 certification in 8 to 10 weeks without external consultants. Those are Kertos numbers rather than audited third-party ones, which is worth stating plainly. The Sifted placement is the independent data point, and it measures growth, which is the market's own verdict on whether the approach works.

What the ranking does not measure

Growth rate is not market share. A leaderboard sorted by CAGR rewards fast expansion from a smaller base, and Sifted says as much in its own disclaimer. Enpal, the highest revenue generator in the ranking at 860 million euros, sits at number 99 because its growth rate is lower.

The ranking also says nothing about compliance outcomes. Passing an ISO 27001 audit still takes work inside the customer's organization, whatever software is involved. Automation changes how much of that work is manual, not whether it has to happen.

Frequently asked questions

Where does Kertos rank in the Sifted 100: DACH & CEE 2026? Kertos ranks 20th of 100, with a two-year revenue CAGR of 248.91%, against a cohort average of 157.61%.

What is the Sifted 100: DACH & CEE? An annual leaderboard from the European technology publication Sifted that ranks the 100 fastest-growing startups across 25 countries by revenue growth over three financial years, measured as a two-year compound annual growth rate. The 2026 edition, published in September 2026, is the third.

Which company ranked first in 2026? Flowpay, a Prague-based embedded lending company, with a two-year CAGR of 816.31%.

Is Kertos the only compliance company in the ranking? Yes. Sifted classifies Kertos as privacy tech, the only entry in that category among the 100 companies, and no other information security or data protection compliance platform appears in the ranking.

How does Kertos compare with compliance platforms in Sifted's other European leaderboards? Sifted published five European leaderboards for 2026: UK and Ireland, Southern Europe, France and Benelux, the Nordics, and DACH and CEE. Kertos is the highest-ranked information security and data protection compliance platform headquartered in the European Union across all five.

What does Kertos do? Kertos provides continuous compliance as a service for European technology companies, combining KAIA, its agentic platform, with certified experts who take on external CISO and DPO mandates. It covers compliance frameworks including ISO 27001, ISO 27701, ISO 42001, GDPR, NIS2, the EU AI Act, SOC 2, TISAX and C5.

What is compliance automation? Software that continuously collects audit evidence, maps controls across frameworks, and keeps policies and records current, in place of manual, point-in-time audit preparation.

The Founder's Guide about NIS2: Prepare your company Now before

Protect your startup: Discover how NIS2 can impact your business and what you need to consider now. Read the free white paper now!

Ready, your compliance to put on autopilot?
Andy Mura

Andy Mura

Head of Marketing

Andy Mura is Head of Marketing at Kertos, where he leads growth strategy for the company's compliance automation platform. A marketer and growth strategist by trade, he has spent years working in highly regulated industries such as payments, which is where his interest in compliance, data privacy, and information security first took root. That foundation has since been sharpened by extensive field research and by ongoing conversations with the CISOs and IT security leaders Kertos serves as customers. He writes about the practical realities of building and running security and compliance programs, drawing on what practitioners tell him works and what does not.

About Kertos

Kertos is the modern backbone of the data protection and compliance activities of scaling companies. We enable our customers to implement integrated data protection and information security processes in accordance with GDPR, ISO 27001, TISAX®, SOC2 and many other standards quickly and cheaply through automation.

Ready to simplify GDPR compliance?

CTA Image

📅 Schedule Your 5min Compliance Check

Please enter your business email to continue. We require a company email address to ensure we can best serve your organization.

📞 5min Compliance Check